[Bug 988920] Re: Token authentication for a user in a disabled tenant does not raise Unauthorized error
Russell Bryant
988920 at bugs.launchpad.net
Fri Sep 28 15:22:22 UTC 2012
Please review this vulnerability description. Once confirmed, it will
go out in an OSSA.
Title: Token authorization for a user in a disabled tenant is allowed
Impact: High
Reporter: Rohit Karajgi (NTT Data)
Affects: Essex (prior to 2012.1.2), Folsom (prior to folsom-3 development milestone)
Description:
Rohit Karajgi reported a vulnerability in Keystone. It was possible to get a token that is authorized for a disabled tenant. Once the token is established with authorization on the tenant, keystone would respond 200 OK to token validation requests from other OpenStack services, allowing the user to work with the tenant's resources.
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to keystone in Ubuntu.
https://bugs.launchpad.net/bugs/988920
Title:
Token authentication for a user in a disabled tenant does not raise
Unauthorized error
To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/988920/+subscriptions
More information about the Ubuntu-server-bugs
mailing list